Cloud computing has become a widely adopted technology for businesses of all sizes across the globe due to its flexibility, scalability, and cost-effectiveness. However, cloud-based infrastructure sees the growing frequency of cyber-attacks leading to an increased demand for effective digital forensic investigations in the cloud.
Managing digital forensics in the cloud is a daunting task. There are multiple reasons for this: the complexity of different cloud deployment models, a lack of appropriate forensics tools fit for cloud investigations, the volatility of the crime scene in the cloud, and the absence of respective standards and frameworks, to name a few.
This lecture aims to provide an overview of various digital forensic processes with respect to cloud deployment models and highlight the challenges and limitations of using traditional methodologies for collecting and preserving digital evidence in cloud forensics.
Finally, it proposes recommendations for setting up a cloud environment in a way that establishes technical prerequisites for conducting cloud forensics, ultimately enabling investigators to collect, analyse, manage, and preserve digital evidence in a court-admissible manner.